Ukraine's CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence. [...]
Individuals connected to transnational cyber-scam operations face U.S. visa restrictions under a new policy announced by Secretary of State Marco Rubio.
A threat actor posting as konata_izumi_shell claims to have breached a system belonging to Bolivia's Ministry of Health and Sports and extracted the complete database behind the Servicio Social de Salud Rural Obligatorio, the programme under which health sciences students and graduates carry out mandatory placements in rural and understaffed facilities.
Google 因搜索和应用商店服务违反在线竞争法,被欧盟处以总计 8.9 亿欧元的罚款。欧洲委员会表示,Google 违反了 Digital Markets Act(DMA),在搜索结果中优先展示自家服务如购物和酒店而非竞争对手的服务。Google 还通过阻止应用开发者引导消费者前往更便宜的网站或替代应用商店购买而违反了 DMA。Google 因搜索相关违规被罚款 4.6 亿欧元,因应用商店违规被罚款 4.3 亿欧元。欧盟委员会命令 Google 以“公平且无歧视的方式”对待在搜索结果中出现的第三方服务,允许应用开发者在 Google 应用商店之外提供优惠。欧盟委员会指出,Google 已开始测试调整其搜索结果中自家服务的展示方式,称这些变化“在合规方面取得了实质性进展”。
A vulnerability classified as problematic was found in NLnet Labs Unbound up to 1.6.2/1.25.1. Affected is an unknown function of the component Respip. The manipulation results in open redirect.
This vulnerability is identified as CVE-2026-50243. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability has been found in NLnet Labs Unbound up to 1.25.1 and classified as very critical. Affected is an unknown function of the component NSEC Handler. This manipulation of the argument RRSIG.Labels causes injection.
This vulnerability is registered as CVE-2026-44690. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
A vulnerability was found in NLnet Labs Unbound up to 1.25.1. It has been classified as critical. Affected by this issue is some unknown functionality. Performing a manipulation results in authentication bypass by capture-replay.
This vulnerability is reported as CVE-2026-46582. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability classified as critical has been found in NLnet Labs Unbound up to 1.25.1. This impacts an unknown function of the component DNSSEC. The manipulation leads to allocation of resources.
This vulnerability is referenced as CVE-2026-50045. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability has been found in NLnet Labs Unbound up to 1.25.1 and classified as critical. This affects an unknown part of the component DoT Forwarding. Performing a manipulation results in use after free.
This vulnerability is cataloged as CVE-2026-50046. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
A vulnerability identified as problematic has been detected in NLnet Labs Unbound up to 1.25.1. Impacted is the function libworker_alloc_cleanup of the component Function Call Allow List. This manipulation of the argument unwanted-reply-threshold causes improper input validation.
This vulnerability is handled as CVE-2026-44621. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
A vulnerability labeled as critical has been found in NLnet Labs Unbound up to 1.25.1. The affected element is an unknown function of the component harden-below-nxdomain. Such manipulation leads to off-by-one.
This vulnerability is uniquely identified as CVE-2026-44687. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
A vulnerability, which was classified as critical, has been found in NLnet Labs Unbound up to 1.25.1. This affects an unknown function of the component Downstream DoQ Implementation. The manipulation leads to allocation of resources.
This vulnerability is listed as CVE-2026-32665. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.